CVE-2016-10168

Description

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.655

Associated Vulnerability

VulnerabilityOS Platform
GD Graphics Library (USN-3030-1) libgd2-xpm_2.0.36~rc1~dfsg-6ubuntu2.4_i386.debLinux
GD Graphics Library (USN-3030-1) libgd2-xpm_2.0.36~rc1~dfsg-6ubuntu2.4_amd64.debLinux
GD Graphics Library (USN-3030-1) libgd2-noxpm_2.0.36~rc1~dfsg-6ubuntu2.4_i386.debLinux
GD Graphics Library (USN-3030-1) libgd2-noxpm_2.0.36~rc1~dfsg-6ubuntu2.4_amd64.debLinux
GD Graphics Library (USN-3410-1) libgd3_2.2.1-1ubuntu3.3_i386.debLinux
GD Graphics Library (USN-3410-1) libgd3_2.2.1-1ubuntu3.3_amd64.debLinux
GD Graphics Library (USN-3213-1) libgd3_2.2.1-1ubuntu3.3_i386.debLinux
GD Graphics Library (USN-3213-1) libgd3_2.2.1-1ubuntu3.3_amd64.debLinux
GD Graphics Library (USN-3213-1) libgd2-xpm_2.0.36~rc1~dfsg-6ubuntu2.4_i386.debLinux
GD Graphics Library (USN-3213-1) libgd2-xpm_2.0.36~rc1~dfsg-6ubuntu2.4_amd64.debLinux
GD Graphics Library (USN-3213-1) libgd2-noxpm_2.0.36~rc1~dfsg-6ubuntu2.4_i386.debLinux
GD Graphics Library (USN-3213-1) libgd2-noxpm_2.0.36~rc1~dfsg-6ubuntu2.4_amd64.debLinux
Php security update (CESA-2017:3221) php-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-gd-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-cli-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-dba-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-fpm-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-pdo-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-xml-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-intl-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-ldap-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-odbc-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-snmp-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-soap-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-devel-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-mysql-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-pgsql-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-bcmath-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-common-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-pspell-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-recode-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-xmlrpc-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-enchant-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-mysqlnd-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-process-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-embedded-5.4.16-43.el7_4.x86_64.rpmLinux
Php security update (CESA-2017:3221) php-mbstring-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-bcmath-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-cli-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-common-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-dba-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-devel-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-embedded-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-enchant-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-fpm-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-gd-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-intl-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-ldap-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-mbstring-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-mysql-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-mysqlnd-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-odbc-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-pdo-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-pgsql-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-process-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-pspell-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-recode-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-snmp-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-soap-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-xml-5.4.16-43.el7_4.x86_64.rpmLinux
(RHSA-2017:3221) Moderate: php security update php-xmlrpc-5.4.16-43.el7_4.x86_64.rpmLinux
SUSE-SU-2017:0468-1(SUSE Linux Enterprise Desktop 12-SP1 ) gd-2.1.0-23.1.x86_64.rpmLinux
SUSE-SU-2017:0468-1(SUSE Linux Enterprise Desktop 12-SP1 ) gd-32bit-2.1.0-23.1.x86_64.rpmLinux
SUSE-SU-2017:0468-1(SUSE Linux Enterprise Desktop 12-SP1 ) gd-debuginfo-2.1.0-23.1.x86_64.rpmLinux
SUSE-SU-2017:0468-1(SUSE Linux Enterprise Desktop 12-SP1 ) gd-debuginfo-32bit-2.1.0-23.1.x86_64.rpmLinux
SUSE-SU-2017:0468-1(SUSE Linux Enterprise Desktop 12-SP1 ) gd-debugsource-2.1.0-23.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234